VulnerabilityModified
CVE-2018-2013
IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the system.
MEDIUM 5.3EPSS 1.76%
Does this matter?
Lower severity and a low EPSS score (1.76%). Track it; it rarely justifies an emergency change on its own.
Description
IBM API Connect 2018.1 through 2018.4.1.5 could disclose sensitive information to an unauthorized user that could aid in further attacks against the system. IBM X-Force ID: 155193.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.76% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- ibm/api connect
- Source
- psirt@us.ibm.com
References
- http://www.securityfocus.com/bid/108907Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/155193VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10882924Patch, Vendor Advisory
- http://www.securityfocus.com/bid/108907Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/155193VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10882924Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.